Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-105744: CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine Vulnerability ID: CVE-2026-105744 CVSS Score: 7.5 Published: 2026-10-07 Docling, a tool for parsing and processing diverse do

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Vulnerability ID: CVE-2026-105744
CVSS Score: 7.5
Published: 2026-10-07

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

TL;DR

A high-severity vulnerability in Docling's optional Tectonic rendering engine allows remote attackers to read arbitrary files, overwrite critical server assets, or execute arbitrary commands via crafted LaTeX inputs containing malicious TikZ macros.

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22, CWE-73, CWE-1188
  • Attack Vector: Network
  • CVSS Score: 7.5 (High)
  • EPSS Score: 0.00304 (Percentile: 21.27%)
  • Exploit Status: Proof of Concept (PoC) available
  • CISA KEV Status: Not Listed

Affected Systems

  • Docling Document Parsing Applications running Tectonic rendering
  • Docling Slim installations with Tectonic engine enabled
  • docling: >= 2.94.0, < 2.132.0 (Fixed in: 2.132.0)
  • docling-slim: >= 2.94.0, < 2.132.0 (Fixed in: 2.132.0)

Code Analysis

Commit: 38b6fa0

Fix TikZ compile path traversal and sandbox Tectonic execution by introducing --untrusted and --only-cached flags and implementing a static LaTeX source validation regex filter

Mitigation Strategies

  • Upgrade the Docling installation to version 2.132.0 or newer.
  • Avoid enabling Tectonic rendering unless required.
  • Isolate document processing within restricted sandbox environments (Docker with read-only filesystems or gVisor).

Remediation Steps:

  1. Run 'pip install --upgrade docling docling-slim' to update package dependencies.
  2. Verify that configurations utilizing LatexBackendOptions explicitly avoid setting 'tikz_engine' to 'tectonic' or 'tikz_engine_allow_shell_escape' to True unless securely sandboxed.

References

Read the full report for CVE-2026-105744 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.